ZeroHour

CVE-2020-7067

PoC
CVSS 3.1
7.5 high
EPSS
4%p91
Published
()
Modified
Description

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

Vendors
phptenableoracledebian
Products
php, tenable.sc, communications diameter signaling router, debian linux
Weakness
CWE-125, CWE-196
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.